<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://cve.autoarticles.net/cve/CVE-2026-63030</loc>
    <news:news>
      <news:publication>
        <news:name>脆弱性対応ウォッチ</news:name>
        <news:language>ja</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:13:32+09:00</news:publication_date>
      <news:title>CVE-2026-63030 WordPress コアの REST API バッチ経路の取り違えで SQLインジェクションからRCEに至る</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cve.autoarticles.net/cve/CVE-2026-0770</loc>
    <news:news>
      <news:publication>
        <news:name>脆弱性対応ウォッチ</news:name>
        <news:language>ja</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:13:32+09:00</news:publication_date>
      <news:title>CVE-2026-0770 Langflow の validate エンドポイントで未認証の任意コード実行が可能</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cve.autoarticles.net/cve/CVE-2026-60137</loc>
    <news:news>
      <news:publication>
        <news:name>脆弱性対応ウォッチ</news:name>
        <news:language>ja</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:13:32+09:00</news:publication_date>
      <news:title>CVE-2026-60137 WordPress コアの author__not_in パラメータで SQLインジェクションが起きる</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cve.autoarticles.net/cve/CVE-2026-35278</loc>
    <news:news>
      <news:publication>
        <news:name>脆弱性対応ウォッチ</news:name>
        <news:language>ja</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T10:10:06+09:00</news:publication_date>
      <news:title>CVE-2026-35278 Oracle PeopleSoft PeopleTools 未認証RCE（Environment Management Hubへ資格情報不要のHTTPで悪用・ShinyHunters実害）</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cve.autoarticles.net/cve/CVE-2026-56188</loc>
    <news:news>
      <news:publication>
        <news:name>脆弱性対応ウォッチ</news:name>
        <news:language>ja</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T10:10:06+09:00</news:publication_date>
      <news:title>CVE-2026-56188 Windows Server ネットワークドライバの未認証RCE（悪意あるネットワークトラフィックで任意コード実行）</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cve.autoarticles.net/cve/CVE-2026-55944</loc>
    <news:news>
      <news:publication>
        <news:name>脆弱性対応ウォッチ</news:name>
        <news:language>ja</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T10:10:06+09:00</news:publication_date>
      <news:title>CVE-2026-55944 Microsoft Dynamics 365 Business Central / NAV デシリアライズによる未認証RCE</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cve.autoarticles.net/cve/CVE-2026-63767</loc>
    <news:news>
      <news:publication>
        <news:name>脆弱性対応ウォッチ</news:name>
        <news:language>ja</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T10:09:54+09:00</news:publication_date>
      <news:title>CVE-2026-63767 ktransformers の ZMQ ソケットで未認証の pickle デシリアライズにより任意コマンドが実行できる</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cve.autoarticles.net/cve/CVE-2026-63766</loc>
    <news:news>
      <news:publication>
        <news:name>脆弱性対応ウォッチ</news:name>
        <news:language>ja</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T10:09:54+09:00</news:publication_date>
      <news:title>CVE-2026-63766 GPT-SoVITS の webui.py で未認証の OS コマンドインジェクションが可能</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cve.autoarticles.net/cve/CVE-2026-64625</loc>
    <news:news>
      <news:publication>
        <news:name>脆弱性対応ウォッチ</news:name>
        <news:language>ja</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T10:09:54+09:00</news:publication_date>
      <news:title>CVE-2026-64625 AVideo の Live プラグインで OS コマンドインジェクション（CVE-2026-45578 の修正不備）</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cve.autoarticles.net/cve/CVE-2026-9135</loc>
    <news:news>
      <news:publication>
        <news:name>脆弱性対応ウォッチ</news:name>
        <news:language>ja</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T22:26:19+09:00</news:publication_date>
      <news:title>CVE-2026-9135 IBM Langflow ToolGuard 経由のコード実行（allow_custom_components=false を迂回）</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cve.autoarticles.net/cve/CVE-2026-64620</loc>
    <news:news>
      <news:publication>
        <news:name>脆弱性対応ウォッチ</news:name>
        <news:language>ja</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T22:26:19+09:00</news:publication_date>
      <news:title>CVE-2026-64620 FreeRDP crypto_rsa_common() のヒープバッファオーバーフロー（RDPサーバ側・未認証で発火）</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cve.autoarticles.net/cve/CVE-2026-45568</loc>
    <news:news>
      <news:publication>
        <news:name>脆弱性対応ウォッチ</news:name>
        <news:language>ja</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T22:26:19+09:00</news:publication_date>
      <news:title>CVE-2026-45568 zrok Python SDK ProxyShare の絶対URL受け入れによるSSRF（urljoin でターゲットホストを差し替え）</news:title>
    </news:news>
  </url>
</urlset>